Knowledge Management

Streamed search execute failed Error in 'SearchParser'

bgaignon
Path Finder

Hi,

This morning I updated my splunk servers to Splunk 6.1 (1 SH, 1 Indexer, 1 Deployment)
No errors during the upgrade.
I restart Splunk and he did not complain.

I tried to display a dashboard and I had this error message:

[slpiussplnk02] Streamed search execute failed because: Error in 'SearchParser': Could not find macro 'sep_admin_sourcetype' that takes 0 arguments. Expecting stanza name 'sep_admin_sourcetype'

This message appears on every search, even if it's not related to SEP (symantec Endpoint protection).

I looked for macros.conf into the SH and Indexer and "sep_admin_sourcetype" was here.
Now I don't know where to look.

Tags (2)
0 Karma
1 Solution

bgaignon
Path Finder

Hi,

Do you have the same issue?

I changed multiple things in eventtypes.conf:
I replaced all macro relative to sourcetypes like:

`sep_scan_sourcetype`
by
index=symantec sourcetype=sep12:scan

I use sep12 and my index is symantec, so you might have to tweak it. Another Example:

#### sep:admin
[sep_admin_authentication]
#search = `sep_admin_sourcetype` ("log on succeeded" OR "log on failed")
search = index=symantec sourcetype=sep12:admin ("log on succeeded" OR "log on failed")
#tags = authentication

View solution in original post

0 Karma

bgaignon
Path Finder

Hi,

Do you have the same issue?

I changed multiple things in eventtypes.conf:
I replaced all macro relative to sourcetypes like:

`sep_scan_sourcetype`
by
index=symantec sourcetype=sep12:scan

I use sep12 and my index is symantec, so you might have to tweak it. Another Example:

#### sep:admin
[sep_admin_authentication]
#search = `sep_admin_sourcetype` ("log on succeeded" OR "log on failed")
search = index=symantec sourcetype=sep12:admin ("log on succeeded" OR "log on failed")
#tags = authentication
0 Karma

zowa
Engager

How did you solve it?

0 Karma

bgaignon
Path Finder

OK it was a problem with the Application SplunkForSymantec.

0 Karma

bgaignon
Path Finder

The permission is set to Global.
All apps in Read for everyone and Write for Admin.

0 Karma

somesoni2
Revered Legend

One thing to look here could be the Sharing permission of the macro. Go to Manager » Advanced search » Search macros, select appropriate app context and see if the macro exists and its sharing permission is set to 'All apps' and read/write to appropriate roles.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...